Privacy Policy
Last updated 19 September 2026
Beta notice. GTS Trading is in private beta. This policy describes how the product actually works today and will be updated as it changes. It has not yet been reviewed by a solicitor.
Who we are
GTS Trading (“GTS”, “we”) provides trading-performance analysis software. For UK data protection law, we are the data controller for the personal data described below. Contact: hello@gts-trading.app.
What we collect
- Account details — your email address and a display name.
- Broker connection data — when you connect cTrader, we receive and store an encrypted access token, your trading account identifier, and whether the account is live or demo.
- Trading activity — trades, positions, entry and exit prices, volumes, stop-loss and take-profit levels (original and amended), profit and loss, and timestamps.
- Market data — price candles retrieved from your broker for the periods surrounding your trades.
- Content you create — journal entries, trading plans, strategy rules, risk settings and any messages you send to Wendy.
- Notification preferences — including a push subscription for your device if you enable notifications.
What we do not do
Our connection to cTrader is read-only. GTS cannot place, modify or close trades, and has no access to deposits, withdrawals or your broker login credentials.
We do not sell your data. We do not share it with advertisers. We do not use it to train AI models.
Why we use it
To provide the service you signed up for: showing you your own trading, identifying patterns in it, and generating the coaching and analysis features. We also use it to operate and secure the service, and to respond to you when you get in touch. Our lawful basis is performance of our contract with you, and our legitimate interest in keeping the service secure and working.
Who we share it with
We use a small number of processors to run the service:
- Supabase — database and authentication.
- Netlify — website and application hosting.
- Anthropic — the AI model behind Wendy’s coaching responses.
- Microsoft Azure — text-to-speech, when you use Wendy’s voice.
- Your broker (cTrader) — we read your trading data from them at your instruction.
Some of these providers process data outside the UK. Where that happens, transfers rely on the safeguards in those providers’ own data processing terms.
How we protect it
- Broker access tokens are encrypted with AES-256-GCM before storage and are never sent to your browser.
- Access to your records is restricted at the database level, so one account cannot read another’s data.
- All traffic is served over HTTPS.
No system is perfectly secure, and we do not claim otherwise.
How long we keep it
We keep your data while your account is open. If you ask us to delete your account, we will remove your personal data and trading records.
Being straight with you: during beta, account deletion and disconnecting your broker are handled manually — email us and we will action it. A self-service button is not built yet. We would rather tell you that than imply a feature exists.
Your rights
Under UK GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable format. Email hello@gts-trading.app and we will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk.
Cookies
We use only what is needed to keep you signed in. We do not use advertising or third-party tracking cookies.
Changes
If we change this policy we will update the date above and, for significant changes, tell you directly.
